255
Limiting user access
Authenticating with an external authentication server
7
After defining the Active Directory authentication server, you can use it in the following ways:
■
Identify the server to be used for authentication in an authentication scheme.
■
Use the server as the authentication server in a clientless VPN role.
Related information
For further information related to this topic, see the following:
■
“Active Directory Properties—General tab”
■
“Active Directory Properties—Description tab”
■
“Configuring an authentication scheme”
■
“Creating and assigning roles”
Lightweight Directory Access Protocol (LDAP) authentication
The security gateway supports LDAP authentication using an LDAP version 3 directory. LDAP,
although not a strong authentication method, is flexible with respect to the directory schema and
organization (the attributes and object classes used in the configuration). LDAP authentication is
performed by binding to the user’s Distinguished Name (DN) using their user ID (UID). LDAP looks up
the DN using the UID and the UID attribute from the configuration. The password is then used to bind
to the entry.
A group list can be retrieved by searching for groups where the user’s DN (or other specified unique
attribute) is a member specified in the configuration. If no primary group attribute is specified, the
first one of the group list is returned as the primary group. Access is denied if multiple users exist with
the same UID attribute and the denial is logged.
Prerequisites
None.
To create a new LDAP authentication server record
1
In the SGMI, in the left pane, under Assets, click
Authentication Servers
.
2
In the right pane, on the Authentication Servers tab, click
New > LDAP
.
3
In the LDAP Properties dialog box, on the General tab, do the following:
Name
Type a name for this authentication server.
SSL based
Check this box if you want to use the secure LDAP protocol.
Primary server
Type the fully-qualified DNS name or IP address of system on which the native LDAP
server application is running.
Primary server port
Type the TCP port number assigned to the LDAP directory server.
Alternate server
Type the fully-qualified DNS name or IP address of the system on which an alternate
LDAP directory server is running.
Alternate server port
Type the TCP port number assigned to the LDAP directory server.
Caption
Type a brief description of the LDAP server.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...